Galaxy says Coldcard exploit losses reach 1,367 BTC as exchange inflows rise

Galaxy says Coldcard exploit losses reach 1,367 BTC as exchange inflows rise

Researchers said the Coldcard sweep attack on vulnerable single-signature wallets remained active, with 4,585 affected addresses, roughly $88.6 million in stolen Bitcoin and signs users were shifting custody after the incident.

BTC

Fact Check
The Galaxy Research X post itself states the exact figures in the claim: 1,196 addresses drained for 1,082.65 BTC. The stated window (01:10:20-01:51:26 UTC) is precisely 41 minutes, matching the claim. The Block independently reports the same numbers and the $70M+ Coldcard vulnerability framing. Coinkite's official advisory confirms the underlying seed-generation flaw and emergency firmware fixes. All specific claim elements are corroborated by primary and independent sources.
    Reference123
Summary

Galaxy Research said an active sweep attack tied to weak random number generation in certain Coldcard single-signature wallets had reached 1,367.05 BTC, or about $88.6 million, across 4,585 addresses. Investigators said the stolen Bitcoin appeared to remain largely unspent, suggesting the attacker may still be consolidating funds, while July 31 data showed net Bitcoin exchange inflows of 11,163 BTC and a jump in sub-1 BTC transfers as users reacted to the incident. The exploit also widened debate over self-custody after comments from Ari Paul and Erik Voorhees.

Terms & Concepts
  • random number generator vulnerability: A weakness in entropy generation that can make wallet seeds or keys more predictable to attackers.
  • self-custody: Holding crypto directly by controlling the private keys rather than relying on an intermediary.
  • net inflows: A measure showing that more coins entered exchanges than left them over a given period.